The caller knows your name and says they are helping with your account. That knowledge is not authentication. Before discussing a balance, approving a notification or installing anything, establish who contacted you through a channel you found independently. A convincing introduction should not decide who gets access to your money.

Account security works better as a sequence of controls than as one impressive setting. Protect the sign-in, protect recovery, limit what connected tools can do and prepare a response for anything you did not authorise.

Secure the email account behind the account

Start with the email address used for registration. The UK's National Cyber Security Centre treats email recovery and account security as important parts of recovering from compromise. If you use email to reset a trading password, include it in the same security review.

Use a unique password for every service, with a password manager if that helps you maintain them. The NCSC recommends this approach because a reused credential links otherwise separate accounts. Do not make the trading password merely a small variation of your email password.

Review recovery addresses, telephone numbers and active sessions. Remove access you do not recognise and investigate unexpected forwarding rules. Keep your device and browser updated, and avoid conducting the setup through links supplied in an unsolicited message.

Create a reliable route back to the genuine service. A bookmark saved after checking the official address is more useful than repeatedly following whatever message happens to arrive next.

Choose authentication with its limitations in mind

Two-factor authentication adds a check beyond a password, but methods do not offer identical protection. CISA's mobile-security guidance distinguishes SMS codes, authenticator codes and phishing-resistant FIDO methods. Check which options your provider actually supports.

An authenticator code still needs careful handling: do not read it to a caller or enter it into a page reached through suspicious contact. Treat an unexpected approval request as something to investigate, not an interruption to dismiss by accepting.

FIDO explains that passkeys are bound to the genuine service, which helps resist fake sign-in pages. That benefit does not authorise a stranger to manage your device or tell you which transfer to approve.

If you use a security key or passkey, understand the fallback process as well. Identify where it is stored, how a replacement device gains access and what happens if the device is lost. A strong sign-in method should be paired with recovery you understand.

Prepare recovery before replacing your phone

The NCSC recommends keeping recovery information available even if normal account access is lost. Choose storage that does not depend entirely on the same phone or email account you might need to recover.

Before changing devices, list the services affected: email, trading account, authenticator and any password or credential manager. Confirm each provider's transfer or recovery instructions while the old device still works. Do not erase it first and discover the missing requirement afterwards.

Store recovery codes securely and keep them private. They are a way to regain access, not a verification document to send to support. Check whether using a code invalidates it and whether the service issues replacement codes.

A useful exercise is to explain your recovery route without opening the trading account. If the explanation ends with “I will ask whoever calls me”, replace that uncertainty with an independently verified support route.

Make callers prove the channel, not their knowledge

The FTC warns that caller ID can be spoofed. Familiar details and a familiar number should therefore be treated as context, not proof of identity. The practical test is whether you can verify the interaction through the organisation's genuine website or application.

XTZ Swap registration starts with a phone call. Expecting that call does not remove the need to verify contact. Its sign-up form does not make a deposit or begin trading, so submitting it is not a reason to rush an unexpected payment request.

If a conversation becomes suspicious, end it and initiate a new contact using details you obtained independently. Do not use a replacement link or telephone number supplied by the same caller as the only verification.

Never hand over passwords, recovery codes or wallet recovery phrases. Do not install remote-access software at an unsolicited caller's request. A claim that urgent action is needed should prompt independent checking before an account action, not replace it.

Limit withdrawals and connected tools

Some services offer withdrawal address lists that restrict transfers to approved destinations. Coinbase documents one implementation, but availability and settings vary. If your provider offers a list, inspect how addresses are added, changed and confirmed.

Check the whole address and network against the intended recipient's verified instructions. A saved entry is only useful if it was correct when created. Review whether changing the list generates a notification or introduces a delay, without assuming either protection is universal.

API keys deserve a separate review. Kraken's security documentation recommends limiting permissions and revoking suspicious keys. Ask what the connected tool actually needs. Do not grant withdrawal permission merely because a setup guide displays an all-permissions option.

Keep a record of connected applications and remove unused access. Where supported, consider restrictions such as permitted IP addresses or expiry. Do not assume that changing your main password also revokes every existing session and connection; check those controls directly.

Respond to suspicious activity in a clear order

Use a device you trust and open the provider's verified app or website. If an account-lock feature exists, inspect how to activate it. Contact support through that independent route and secure the associated email if it might also be compromised.

Following the NCSC's recovery guidance, review passwords, sessions, devices and recovery settings. Revoke unknown API keys and connected applications. Inspect withdrawal destinations, recent orders, balances and completed transfers. Each check answers a different question about what an attacker may have changed.

Preserve suspicious messages, transaction identifiers and security alerts. Contact your bank or payment provider if a payment is involved, and report suspected theft through the appropriate local channel. Do not pay an unsolicited “recovery agent” on the strength of a promise to return funds.

Strong account controls cannot prevent every loss in crypto trading.